mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-01 02:59:08 +02:00
Small refactor of Authz
This commit is contained in:
@@ -1,5 +1,9 @@
|
||||
package ipcauth
|
||||
|
||||
import (
|
||||
"github.com/netbirdio/netbird/client/proto"
|
||||
)
|
||||
|
||||
const servicePath = "/daemon.DaemonService/"
|
||||
|
||||
// Request is what a rule decides on: the authorization plus the state and the
|
||||
@@ -50,6 +54,25 @@ type MethodPolicy struct {
|
||||
Command string
|
||||
}
|
||||
|
||||
// RequireHolderForFullStatus escalates a StatusRequest that asks for peer detail
|
||||
// or for probes to be run.
|
||||
func RequireHolderForFullStatus(r Request) error {
|
||||
statusReq, ok := r.Msg.(*proto.StatusRequest)
|
||||
if !ok {
|
||||
return nil
|
||||
}
|
||||
if r.Level < AuthzLevelSessionHolder {
|
||||
if statusReq.GetFullPeerStatus {
|
||||
statusReq.GetFullPeerStatus = false
|
||||
}
|
||||
if statusReq.ShouldRunProbes {
|
||||
statusReq.ShouldRunProbes = false
|
||||
}
|
||||
return nil
|
||||
}
|
||||
return RequireLevel(AuthzLevelSessionHolder)(r)
|
||||
}
|
||||
|
||||
// methodPolicies is the complete authorization surface. Every RPC on
|
||||
// DaemonService appears here exactly once.
|
||||
var methodPolicies = map[string]MethodPolicy{
|
||||
|
||||
Reference in New Issue
Block a user